Sign inSign up
Ruby

dhi.io/ruby

Ruby 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.10-debian-fips, 3.4.10-debian13-fips, 3.4.10-fips

Index digest:

sha256:cf3f543ed8ba803386067b3d3dba04cb6ff47dbbcd5d2c5b824525ed0cd4ea38

Manifest digest:

sha256:23417c75106ebef7918700b4a707ae21761f714c4d52bb6ab305c2c4a58988e9

Size

21.07 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active until Mar 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ruby:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ruby:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ruby@sha256:6511c24927b9dbac89fc5ecfe43b8f80168da3ea41c5c53fc61a9cf4cddbd852
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ruby@sha256:ca8ce7370cb206e93ffe20ac38f720f52a3384d60636baa6a514e43c4440f88c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ruby@sha256:7f0312d42a514c4a94dff4d0860dde276c45f50d0a86cbf2029713c48bbaa3b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ruby@sha256:4e75aef09ecc62ad0a2937bb47069cabb0873d5fb2f9c74594da51e832c4f68f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ruby@sha256:3119d73e97745e2e5c0a03e1328ac45d26ba408ac6f762ef15e00043ae73a615
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ruby@sha256:8af789317355413a0bad89c73e31985a98f3145b91275d9dd52b3358b3c26369
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ruby@sha256:5cb39f1147badcac6e37b2e859e513e0826ad0b8240e1f2ffa81b6a3533f8830
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ruby@sha256:410418c5ecc67da161a81d8523de7651e5240fb4ae3c7a899dcef4d894216b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ruby@sha256:3399ca00a90ce1737fbfc68b908d1d6c24b7f0affca50a9bdbbd6e4bbe7e1b62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ruby@sha256:6d8b636b17668377a19d933e8737647d15d29027e0dce6673c60a99fac5f17e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ruby@sha256:3c941b1dfe3a4b5e0159ea31ce7792f08437726ad394c2ba7ab48e66b4b09dbe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ruby@sha256:1709ac0f2e10d3c873331b60ee4e9a2b7e3ffa3b6cf60c7fa8d3ed0f8002cf1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ruby@sha256:b037c0e545290e5c94f2492ee6c2aeffdc1480b755fe84bb849eb561c53fa3f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ruby@sha256:3327198c545b725c300cba0c0fc2c52a391e770ceb29673fed3eb8cd3d854ecc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ruby@sha256:64b2204ddc056e38217b5705af41f18d129e26a860c11c250b60178ed78443ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ruby@sha256:64239365d6b7fafd59164148193352eb417f5add0fea17a8e628120fcce093fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ruby@sha256:46ab63419e106b5ea488ba648262dde27f14678b4ce5082056c5e445c62fc10f